20-24
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 20 Queries and Reports
Reports
Report Type Views: Total vs. Peak vs. Recent
Where alerts provide up-to-the-minute views of high-priority incidents, reports aggregate sessions into
different views. Reports correlate based on the three data points:
•
Period of time
•
Query criteria
•
View type
The
period of time
defines boundaries around the analyzed session data based on when it was recorded.
Query criteria
restrict the set of sessions that will be aggregated to that which matches your criteria.
Criteria can include source address, destination address, network service, event, reported user, and
reporting device. The
view type
defines how to aggregate the matched data into a meaningful report
view—one that matches the type of study in which you are interested.
Note
In each view type, you can refine the report criteria to filter out expected activity—the data you know
about. You can filter this activity by refining the query criteria. These criteria should be tuned to a
specific network. Reports can be valuable in detecting behaviors beyond the normal traffic flows of your
network. You can determine the expected activities using reports that are not filtered and vetting those
results against normal network use.
MARS provides three view types, each of which restricts the matched sessions to a user-defined limit of
N
. The following view types exist:
•
Total View
. For each result type matching the query criteria, this view counts the occurrences of
that result type that transpire during the specified time period. It presents the total count of the top
N
matched result types, ranked by number of sessions, as determined by which ones occurred most
frequently over the period of time. You can use these reports to determine your network’s condition
relative to the studied sessions. For example, you can use this view to identify attacks that launched
at frequent intervals. This view does not present spikes in network activity; it simply presents the
top occurring result types.
•
Peak View
. Within MARS, all report result data is stored in 10-minute time slices. The Peak View
studies each of the 10-minute time slices within the specified time period to which one contained
the highest number of matched sessions for a specific result type. It also determines an additional
nine peaks within the time period, where each peak identifies a unique result type relative to the
other peaks.
Each peak value is charted relative to the other nine peaks. For each time slice containing a peak value,
the Peak View lists the top
N
matched result types that occurred. It is possible to have multiple peaks
within the same time slice, as it is the result type, not the time slice, that must be unique across peaks.
Note
To be detected within this view, the result type must peak above normal traffic. Therefore, you must tune
the query data to filter out expected traffic.
1.
Table values are for Cisco Security MARS Release 4.1.5. In Release 4.1.4 and prior, the maximum number of ranking reports
is 100, maximum number of event/session reports is 1,000.
2.
As of Cisco Security MARS Release 4.1.5. In Release 4.1.3, and 4.1.4, report results are retained for one year in the MARS
database before they are automatically purged. In Releases prior to Release 4.1.3, report results are retained indefinately. The
purge interval cannot be changed.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...